SecMANO: Towards Network Functions Virtualization (NFV) based Security MANagement and Orchestration

被引:0
|
作者
Pattaranantakul, Montida [1 ,2 ]
He, Ruan [3 ]
Meddahi, Ahmed [2 ]
Zhang, Zonghua [2 ]
机构
[1] TELECOM SudParis, Inst Mines Telecom, F-91011 Evry, France
[2] TELECOM Lille, Inst Mines Telecom, F-59650 Villeneuve Dascq, France
[3] Orange Labs, F-92130 Issy Les Moulineaux, France
来源
2016 IEEE TRUSTCOM/BIGDATASE/ISPA | 2016年
关键词
Network Function Virtualization (NFV); Software Define Network (SDN); threat analysis; security management; service orchestration;
D O I
10.1109/TrustCom.2016.114
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network Functions Virtualization (NFV) has recently emerged as one of the major technological driving forces that significantly accelerate the evolution of today's computer and communication networks. Despite the advantages of NFV, e.g., saving investment cost, optimizing resource consumption, improving operational efficiency, simplifying network service lifecycle management, lots of novel security threats and vulnerabilities will be introduced, thereby impeding its further development and deployment in practice. In this paper, we briefly report our threat analysis in the context of NFV, and identify the corresponding security requirements. The purpose is to establish a comprehensive threat taxonomy and provide a guideline to develop effective security countermeasures. Furthermore, a conceptual design framework for NFV based security management and service orchestration is presented, with an objective to dynamically and adaptively deploy and manage security functions on the demands of users and customers. A use case about NFV based access control is also developed, illustrating the feasibility and advantages of implementing NFV based security management and orchestration.
引用
收藏
页码:598 / 605
页数:8
相关论文
共 50 条
  • [1] Management and Orchestration Challenges in Network Functions Virtualization
    Mijumbi, Rashid
    Serrat, Joan
    Gorricho, Juan-Luis
    Latre, Steven
    Charalambides, Marinos
    Lopez, Diego
    IEEE COMMUNICATIONS MAGAZINE, 2016, 54 (01) : 98 - 105
  • [2] Modeling and Mitigating Security Threats in Network Functions Virtualization (NFV)
    Alhebaishi, Nawaf
    Wang, Lingyu
    Jajodia, Sushil
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXIV, DBSEC 2020, 2020, 12122 : 3 - 23
  • [3] Quality Audit and Resource Brokering for Network Functions Virtualization (NFV) Orchestration in Hybrid Clouds
    Carella, Giuseppe
    Foschini, Luca
    Pernafini, Alessandro
    Bellavista, Paolo
    Corradi, Antonio
    Corici, Marius
    Schreiner, Florian
    Magedanz, Thomas
    2015 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2015,
  • [4] Towards an Efficient Management and Orchestration Framework for Virtual Network Security Functions
    Pedone, Ignazio
    Lioy, Antonio
    Valenza, Fulvio
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
  • [5] NFVGuard: Verifying the Security of Multilevel Network Functions Virtualization (NFV) Stack
    Oqaily, Alaa
    Sudershan, L. T.
    Jarraya, Yosr
    Majumdar, Suryadipta
    Zhang, Mengyuan
    Pourzandi, Makan
    Wang, Lingyu
    Debbabi, Mourad
    2020 IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2020), 2020, : 33 - 40
  • [6] Adaptive Network Security Service Orchestration Based on SDN/NFV
    Ganta, Priyatham
    Yu, Kicho
    Chintala, Dharma Dheeraj
    Park, Younghee
    INFORMATION SECURITY APPLICATIONS, 2021, 13009 : 231 - 242
  • [7] Towards Novel Security Architectures for Network Functions Virtualization
    Repetto, M.
    Carrega, A.
    Lamanna, G.
    2019 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (IEEE NFV-SDN), 2019,
  • [8] Recent activities on network functions virtualization (NFV)
    Shimonishi, Hideyuki
    Journal of the Institute of Electronics, Information and Communication Engineers, 2015, 98 (03): : 225 - 231
  • [9] Use Case of a Management and Orchestration for Network Functions Virtualization in a VoIP Testbed
    Kone, Benjamin
    Kora, Ahmed Dooguy
    Botez, Robert
    Ivanciu, Iustin-Alexandru
    Dobrota, Virgil
    2021 IEEE INTERNATIONAL BLACK SEA CONFERENCE ON COMMUNICATIONS AND NETWORKING (IEEE BLACKSEACOM), 2021, : 261 - 265
  • [10] Towards a fully automated and optimized network security functions orchestration
    Bringhenti, Daniele
    Marchetto, Guido
    Sisto, Riccardo
    Valenza, Fulvio
    Yusupov, Jalolliddin
    2019 4TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATIONS AND SECURITY (ICCCS), 2019,